The Your
Sep 13, 2026
HyperLocal Loop
The Your

Close to home. Always in the loop.

Thousands of Small‑Business Websites Compromised by Fake CAPTCHA Malware Scam

Cybersecurity firm Netskope Threat Labs has uncovered a massive campaign that has infected thousands of legitimate small‑business websites across more than 2,200 organizations worldwide. The attackers embed malicious code that displays a fake CAPTCHA, then instructs visitors to open the Windows Run dialog and paste a command that downloads and launches malware.

How the scam works

When a user lands on a compromised site, the page may appear normal until a blurred screen shows a CAPTCHA‑style prompt. Instead of a simple “click the box” check, the page tells the visitor to open Windows Run (or PowerShell/Command Prompt) and paste a cryptic command. Executing that command gives the attacker full control of the computer, allowing them to install ransomware, spyware, or other malicious payloads.

Scope of the problem

Netskope reports more than 5,400 compromised websites, with several hundred active on any given day and over 300 contacting the malicious infrastructure each weekday. The victims span a wide range of small businesses – from local clinics and plumbing services to online stores – many of which run WordPress or PrestaShop platforms. The researchers have not yet identified the initial vulnerability that allowed the attackers to gain access.

Why the attackers use blockchain

Unusually, the campaign stores its instructions on a smart contract on the BNB Smart Chain test network. By using a blockchain testnet, the criminals obtain inexpensive, hard‑to‑shut‑down infrastructure. The smart contract can be updated at any time, allowing all compromised sites to receive new commands without the attackers having to modify each site individually.

New variant using WebRTC

In addition to the fake CAPTCHA method, Netskope discovered a newer version that bypasses the CAPTCHA entirely. This variant leverages WebRTC, a browser technology normally used for video calls, to create an encrypted data channel that streams malicious code directly to the victim’s browser, avoiding the need to write a file to disk.

What users can do

Experts recommend a few simple habits to stay safe:

  • Never open Windows Run, PowerShell, or Command Prompt from a web page, and never paste commands provided by a website.
  • Recognize that a legitimate CAPTCHA will never require you to change system settings or run commands.
  • Keep antivirus software up to date and enable real‑time protection.
  • Install operating‑system and browser updates through official channels only.
  • If you accidentally follow a suspicious prompt, disconnect from the internet, run a full system scan, and change passwords on a trusted device, enabling multi‑factor authentication where possible.

Advice for website owners

Small‑business owners should audit the integrity of their content‑management system files. Netskope advises checking for unauthorized JavaScript, hidden plugin directories, and outdated plugins. Regularly updating WordPress, PrestaShop, and any extensions, and removing unused plugins, can reduce the attack surface. While the exact initial breach method remains unknown, these best‑practice steps are essential for protecting both the business and its customers.

Bottom line

The fake CAPTCHA scam demonstrates how ordinary‑looking web pages can be weaponized to hand control of a computer to cybercriminals. By staying vigilant, keeping software current, and refusing any web‑based request to run system commands, users can protect themselves and help keep their local businesses safe from this evolving threat.


Original reporting: Fox News (HLL/CB) — read the source article.

OBBM Network Editorial Staff

[email protected]

Editorial team behind OBBM Network — independent, hyper-local journalism syndicated through HyperLocalLoop and OBBM Network TV.

Leave a Reply

Your email address will not be published. Required fields are marked *

Recent News

Trending

Community News

Quick Start Deal

Turn Local Reach Into Real Leads

A monthly bundle that puts your business in front of local audiences across HyperLocal Loop and the OBBM Network — and delivers ready-to-contact buyers to your team.

$500 Per Month
What's Included
  • LeadEngine · 1,000 Contacts Verified, buyer-intent prospects in your market, delivered to your team
  • DataPulse · 1,000 Matches Identify and retarget anonymous visitors to your site
  • Banner Ads · 3 Cities Geo-targeted display placement across HyperLocal Loop in three cities
  • Video Commercial · 3 Cities Your commercial airs on the local OBBM channel in three cities
  • Audio · 10,000 Impressions Podcast ad impressions across the OBBM Network
  • Geo-Targeting City or regional targeting via AdServe
  • Real-Time Reporting Track campaign performance as it happens
Questions about any of this? Ask Ben →
Get Started
Secure checkout · Cancel anytime
Quick Start Deal

Get Loop-Ready in One Move

A low-commitment monthly bundle that keeps your business in front of local audiences across HyperLocal Loop and the OBBM Network.

$350 Per Month
What's Included
  • DataPulse · 1,000 Matches Identify and retarget anonymous visitors to your site
  • Banner Ads Geo-targeted display placement across HyperLocal Loop
  • Video Ad Airs on your Local OBBM Channel
  • Business Advertorial A featured sponsored article telling your story
Questions about any of this? Ask Ben →
Get Started
Secure checkout · Cancel anytime
§ 04 · Choose Your Package

Three levels. Up to 60% off.

Every Patriot Package is priced at over 40% off standard AdRevv list rates — and the discount deepens as you scale, up to 60% off at the Enterprise tier.

Tier I · Local
The Patriot
For local & regional brands launching with the network.
List Price: $835/mo
$500/mo
★ Save $335 — 40% Off
Monthly Allotment
  • Audio: 10,000Podcast impressions
  • Video: 10,000Streaming TV impressions
  • Banners: 50,000HyperLocal Loop geo-targeted banner impressions
  • DataPulse: First 1,000visitor matches included
  • City or regional geo-targeting via AdServe
  • Real-time campaign reporting
Start The Patriot
Tier III · National
The Enterprise
For national brands ready to dominate the network.
List Price: $5,065/mo
$2026/mo
★ Save $3,039 — 60% Off
Monthly Allotment
  • Audio: 14,000Podcast impressions
  • Video: 10,000Streaming TV impressions
  • Banners: 100,000HyperLocal Loop geo-targeted impressions
  • DataPulse: 5,000visitor matches included
  • LeadEngine: 20,000actionable buyer-intent contacts
  • Host Endorsements: 9podcast host-read spots
  • National geo-targeting + dedicated campaign manager
  • Priority creative production support
★ Bonus Included
Free 1-Year Freedom Chamber Membership
Faith, Family & Freedom business community at freedomchamber.net.
Start Enterprise

Need a custom configuration? Build your own package →